Deny Interactive Logon GPO NOT-LINKED to the Domain Controllers Container yet being applied!

Le, Chau 1 Reputation point
2021-04-01T21:05:43.77+00:00

I have a GPO to deny interactive logon linked to Servers OU. In the policy, I'm denying interactive logon to an AD Group called "Deny interactive logon" (I know creative).

This policy IS NOT linked to the Domain Controllers OU.

Yet when I put a domain admin in this group, the policy applies and the domain admin CANNOT RDP to the DC.

Troubleshooting steps
Look at all GP's linked to the Domain Controllers container and none has Deny Interactive Login Setting
Ran a GPO modeling with the DA account and the DC ...exported the report html and search for anything "DENY" and nothing exists in the report with that word

I'm at a lost here why this is being applied to domain controllers when the GP is NOT linked to the domain controller container.

Help please!

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,740 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-04-02T00:19:26.627+00:00

    Hi,

    When " the domain admin CANNOT RDP to the DC", what's the error message?
    Was the domain admin a member of the administrators group?

    Run the cmd on the DC and enter the command as administrator : gpresult /h c:\report.html
    If possible , please share a screenshot here!

    Then check the default domain controller policy ,under the Allow log on through Remote Desktop Services :if the domain admin was added.
    By default, only administrators can rdp to the DCs.

    Best Regards,

    0 comments No comments

  2. Le, Chau 1 Reputation point
    2021-04-02T20:02:59.117+00:00

    Here is the error message... typical deny interactive login

    84152-interactivelogon1.png

    yes the default domain controller policy has allow log on thru remote desktop services with BUILD\Administrator. But for some reason the GPO from the servers OU (a different OU ...not DC OU) is being applied to the DC's.

    I can't run gpresult /h because I can't log in! haha